HW/FW security researcher @ fruit company

Canada
Hello friends. Check out this awesome and unique role that just opened up on my team in SEAR. Wanna secure Apple silicon, ROMs, iBoot, and more? jobs.apple.com/en-us/details…
7
52
170
29,425
Jeremy Boone retweeted
Broadcom and Cypress chips have the same HCI "backdoor" allowing to write to the Bluetooth chip's RAM. This feature is used for firmware patches. We didn't request CVEs for that 9 years ago. Instead, we built the InternalBlue Bluetooth research framework. github.com/seemoo-lab/intern…
🔷 A backdoor in the ESP32 chip would allow it to infect millions of devices. Miguel Tarascó and @antonvblanco have revealed this at the @rootedcon this backdoor and presented a tool to perform Bluetooth security audits on any gadget. tarlogic.com/news/backdoor-e…
4
89
325
40,592
where my peeps on bluesky? @uffeux.bsky.social
1
1
497
Jeremy Boone retweeted
Replying to @evilsocket
any interest in working on security in compilers? my team is looking for someone with a peculiar intersection of skills/interests: jobs.apple.com/en-us/details…
3
14
93
37,246
Jeremy Boone retweeted
Are you excited to use the power of safe modern programming languages like Swift to make software more secure? My SPEAR team at Apple is hiring a Swift Software Engineer to do exactly that! jobs.apple.com/en-us/details…
3
24
48
16,736
Jeremy Boone retweeted
🔺New on the Apple Security Research blog: introducing PQ3, a groundbreaking post-quantum cryptographic protocol for iMessage. To our knowledge, PQ3 has the strongest security properties of any at-scale messaging protocol in the world. security.apple.com/blog/imes…
7
120
356
62,056
that disclosure timeline though...
Is remote code execution in UEFI firmware possible? Yes it is. Meet #PixieFAIL: 9 vulnerabilities in the IPv6 stack of EDK II, the open source UEFI implementation used by billions of computers. Full details by @fdfalcon and @4Dgifts in our new blog post: blog.quarkslab.com/pixiefail…
9
1,082
Jeremy Boone retweeted
Is remote code execution in UEFI firmware possible? Yes it is. Meet #PixieFAIL: 9 vulnerabilities in the IPv6 stack of EDK II, the open source UEFI implementation used by billions of computers. Full details by @fdfalcon and @4Dgifts in our new blog post: blog.quarkslab.com/pixiefail…
4
202
338
78,794
Shooting Yourself in the .flags – Jailbreaking the Sonos Era 100 The Era 100 is Sonos’s flagship device, released on March 28th 2023. NCC found weaknesses within the bootloader which can lead to full compromise of the device. research.nccgroup.com/2023/1… research.nccgroup.com/2023/1…
15
13
40
6,787
Jeremy Boone retweeted
Public Report – Caliptra Security Assessment During August and September of 2023, Microsoft engaged NCC Group to conduct a security assessment of Caliptra v0.9. The assessment identified 26 vulnerabilities, which were promptly addressed by the Caliptra... bit.ly/3SaMNWM
1
1
250
New Blog: Public Report – Caliptra Security Assessment research.nccgroup.com/2023/1…
2
1
616
Jeremy Boone retweeted
Public Report – Caliptra Security Assessment During August and September of 2023, Microsoft engaged NCC Group to conduct a security assessment of Caliptra v0.9. The assessment identified 26 vulnerabilities, which were promptly addressed by the Caliptra... bit.ly/3QoVImr
1
1
209
Pleased to share our public report for Caliptra. Caliptra is an open-source HW/FW that is designed for server-class ASICs, where it acts as a root of trust for measurement. The audit was performed under the umbrella of the @OpenComputePrj's SAFE program. research.nccgroup.com/2023/1…
3
8
2,308
OCP Tackles Data Center Security, Launches New Community-Led Security Program Improving IT Device Security Posture! OCP Security Appraisal Framework Enablement (S.A.F.E.) improves the trustworthiness of devices across all data center IT infrastructure. bit.ly/46ypGde
2
3
758